<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:09:26.596187+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10883</id>
    <title>bdu:2026-10883</title>
    <updated>2026-10-02T22:09:26.676196+00:00</updated>
    <content>bdu:2026-10883</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T22:09:26.676234+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354276</id>
    <title>EUVD-2026-354276</title>
    <updated>2026-10-02T22:09:26.676254+00:00</updated>
    <content>EUVD-2026-354276</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40477</id>
    <title>fkie_cve-2026-40477</title>
    <updated>2026-10-02T22:09:26.676267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r4v4-5mwr-2fwr</id>
    <title>GHSA-r4v4-5mwr-2fwr — Improper restriction of the scope of accessible objects in Thymeleaf expressions</title>
    <updated>2026-10-02T22:09:26.676310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.thymeleaf:thymeleaf, Maven: org.thymeleaf:thymeleaf-spring5, Maven: org.thymeleaf:thymeleaf-spring6</p>
<p>### Impact
A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.3.RELEASE. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI).</p>
<p>### Patches
This has been fixed in Thymeleaf 3.1.4.RELEASE.</p>
<p>### Workarounds
No workaround is available beyond ensuring applications do not pass unvalidated user input directly to the template engine. Upgrading to 3.1.4.RELEASE is strongly recommended in any case.</p>
<p>### Credits
Thanks to Thomas Reburn (Praetorian) for responsible disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r4v4-5mwr-2fwr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21772</id>
    <title>RHSA-2026:21772 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.28.0 Release.</title>
    <updated>2026-10-02T22:09:26.676348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking tar: tar: File overwrite via drive-relative symlink traversal flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnera…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21772"/>
  </entry>
</feed>
